Lana Salameh
Lana Salameh works in the Office of the CTO at Zenity, where she leads innovation initiatives and drives the creation of AI security products from concept to launch - shaping ideas, building proofs of concept, and collaborating closely with development teams to bring them to life. As Zenity’s founding engineer, Lana has been deeply involved both hands-on in building core technologies and in leading teams through key technical and managerial roles since the company’s inception. Before joining Zenity, Lana worked at Microsoft, focusing on cloud security. With over eight years of experience in cybersecurity, she combines deep technical expertise with hands-on development and security research, continuously uncovering emerging threats and exploring how cutting-edge technologies can be harnessed securely - both in the cloud and in the evolving world of AI security.

Posts by Lana Salameh
Security ResearchAgentCorruption: How A Single Prompt Collapsed The Entire Cloud Security Model

Tamir Ishay SharbatandLana Salameh
Security ResearchAgentCorruption: Initial IMDS Access
How a single prompt to a public-facing AgentCore agent exposed the instance metadata endpoint, the agent's cloud identity, and its container image: the foothold for everything that follows in this series.

Lana SalamehandDmitry Lozovoy
Security ResearchAgentCorruption: One Role to Rule Them All
Exploring what the agent's default execution role and stolen credentials can actually do, and how they became an entry point to the entire region - discovering and invoking other agents, reading, deleting and hijacking private conversations through chat history tampering, and more.

Lana SalamehandDmitry Lozovoy
AgentCorruption: Credential Theft from AWS's Secrets Manager and More
Lana Salameh
AgentCorruption: Weaponizing Agent Memory for Persistent Hijacking
How access to AgentCore Memory let us plant instructions that survived beyond the initial compromise, turning an agent's remembered context into a channel for persistent command and control.

João DonatoandLana Salameh
Inside the Agent Stack: Securing Agents in Amazon Bedrock AgentCore
An in-depth examination of emerging risks and effective mitigation techniques for protecting AI agents operating within the Bedrock AgentCore ecosystem.
Lana Salameh
Inside the Agent Stack: Securing Microsoft Foundry-Built Agents
A deep dive into realistic threat scenarios and practical strategies for securing enterprise AI agents built in Microsoft Foundry.
Lana Salameh
Security ResearchPhishing is Dead, Long Live Spear Phishing
Lana Salameh
Security ResearchAccess Copilot for M365 through the terminal
Lana Salameh